CVE

Id
7642  
CVE No.
CVE-2003-0818  
Status
Candidate  
Description
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.  
Phase
Modified (20061101)  
Votes
ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox  
Comments
Christey> Various sources say that Windows Server 2003 is also affected. | | XF:win-asn1-library-bo(15039) | URL:http://xforce.iss.net/xforce/xfdb/15039 | BID:9633 | URL:http://www.securityfocus.com/bid/9633 | EEYE:AD20040210-2 | URL:http://www.eeye.com/html/Research/Advisories/AD20040210-2.html